ff276ed7d9
gates / gates (push) Successful in 4m34s
scripts/facebook/fb_probe.py (stdlib, read + write-test, no real-post command) with tests; read run twice: SYSTEM_USER, expires_at 0, /me/accounts empty, so D/E did not run and nothing was posted. Findings, redacted evidence, CONTEXT decision home, STATUS item, scripts CHANGELOG, REPORT-facebook-page-api.md.
72 lines
2.3 KiB
Python
72 lines
2.3 KiB
Python
#!/usr/bin/env python3
|
|
# -*- coding: utf-8 -*-
|
|
"""Tests for fb_probe.py's two secret-handling seams: the key loader (R-453) and redact()."""
|
|
import os
|
|
import sys
|
|
import tempfile
|
|
import unittest
|
|
|
|
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
|
import fb_probe # noqa: E402
|
|
from read_credential import CredentialError # noqa: E402
|
|
|
|
FAKE = "EAAfakeprobe0123456789abcdef"
|
|
|
|
|
|
def creds(text):
|
|
fd, p = tempfile.mkstemp()
|
|
with os.fdopen(fd, "w") as fh:
|
|
fh.write(text)
|
|
return p
|
|
|
|
|
|
class LoadKey(unittest.TestCase):
|
|
def load(self, text):
|
|
p = creds(text)
|
|
try:
|
|
return fb_probe.load_key(p)
|
|
finally:
|
|
os.unlink(p)
|
|
|
|
def test_single_quotes(self):
|
|
self.assertEqual(self.load("OTHER='x'\nFACEBOOK_API='%s'\n" % FAKE), FAKE)
|
|
|
|
def test_double_quotes_and_export(self):
|
|
self.assertEqual(self.load('export FACEBOOK_API="%s"\n' % FAKE), FAKE)
|
|
|
|
def test_trailing_whitespace_stripped(self):
|
|
self.assertEqual(self.load("FACEBOOK_API='%s' \n" % FAKE), FAKE)
|
|
|
|
def test_mismatched_quote_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_API='%s\"\n" % FAKE)
|
|
|
|
def test_inner_whitespace_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_API='EAA abc'\n")
|
|
|
|
def test_not_a_meta_token_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_API='xyz123'\n")
|
|
|
|
def test_missing_key_refused(self):
|
|
with self.assertRaises(CredentialError):
|
|
self.load("FACEBOOK_APIX='%s'\n" % FAKE)
|
|
|
|
|
|
class Redact(unittest.TestCase):
|
|
def test_access_token_key_dropped_everywhere(self):
|
|
out = fb_probe.redact({"data": [{"id": "1", "access_token": "zzz"}], "access_token": "y"}, secrets=[])
|
|
self.assertEqual(out, {"data": [{"id": "1"}]})
|
|
|
|
def test_held_secret_and_token_shape_replaced(self):
|
|
out = fb_probe.redact({"a": "pre-sekret-post", "b": "x " + FAKE, "c": "fine"}, secrets=["sekret"])
|
|
self.assertEqual(out, {"a": "[REDACTED]", "b": "[REDACTED]", "c": "fine"})
|
|
|
|
def test_hungarian_text_survives(self):
|
|
self.assertEqual(fb_probe.redact(fb_probe.TEST_TEXT, secrets=[]), fb_probe.TEST_TEXT)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|